Deserialization of Untrusted Data in NukeViet - CVE-2026-61832

 

Deserialization of Untrusted Data in NukeViet - CVE-2026-61832

Published: July 24, 2026


Vulnerability identifier: #VU139331
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61832
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in extension store management handlers when processing an unverified HTTP response body. A remote attacker can substitute the response body with a crafted PHP serialized payload to execute arbitrary code.

Exploitation requires a privileged administrator to perform a store action such as opening the store list, install, update, or detail, and requires the ability to intercept or alter outbound traffic to the store endpoint.


Affected software

NukeViet

How to mitigate CVE-2026-61832

Install security update from vendor's website.

NukeViet - update to 4.6.00

External References

Related Security Bulletins